Search Results (322297 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-14748 1 Osticket 1 Osticket 2024-11-21 N/A
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upload files along with queries. It was found that the file-upload functionality has fewer (or no) mitigations implemented for file content checks; also, the output is not handled properly, causing persistent XSS that leads to cookie stealing or malicious actions. For example, a non-agent user can upload a .html file, and Content-Disposition will be set to inline instead of attachment.
CVE-2019-14747 1 Diaowen 1 Dwsurvey 2024-11-21 N/A
DWSurvey through 2019-07-22 has stored XSS via the design/my-survey-design!copySurvey.action surveyName parameter.
CVE-2019-14746 1 Kuaifan 1 Kuaifancms 2024-11-21 N/A
A issue was discovered in KuaiFanCMS 5.0. It allows eval injection by placing PHP code in the install.php db_name parameter and then making a config.php request.
CVE-2019-14745 2 Fedoraproject, Radare 2 Fedora, Radare2 2024-11-21 7.8 High
In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerability is due to improper handling of symbol names embedded in executables.
CVE-2019-14744 6 Canonical, Debian, Fedoraproject and 3 more 10 Ubuntu Linux, Debian Linux, Fedora and 7 more 2024-11-21 7.8 High
In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.
CVE-2019-14743 2 Microsoft, Valvesoftware 2 Windows, Steam Client 2024-11-21 N/A
In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group, which allows local users to gain NT AUTHORITY\SYSTEM access.
CVE-2019-14737 1 Ubisoft 1 Uplay 2024-11-21 7.8 High
Ubisoft Uplay 92.0.0.6280 has Insecure Permissions.
CVE-2019-14734 2 Adplug Project, Fedoraproject 2 Adplug, Fedora 2024-11-21 8.8 High
AdPlug 2.3.1 has multiple heap-based buffer overflows in CmtkLoader::load() in mtk.cpp.
CVE-2019-14733 2 Adplug Project, Fedoraproject 2 Adplug, Fedora 2024-11-21 8.8 High
AdPlug 2.3.1 has multiple heap-based buffer overflows in CradLoader::load() in rad.cpp.
CVE-2019-14732 2 Adplug Project, Fedoraproject 2 Adplug, Fedora 2024-11-21 8.8 High
AdPlug 2.3.1 has multiple heap-based buffer overflows in Ca2mLoader::load() in a2m.cpp.
CVE-2019-14731 1 Cnezsoft 1 Zentao 2024-11-21 N/A
An issue was discovered in ZenTao 11.5.1. There is an XSS (stored) vulnerability that leads to the capture of other people's cookies via the Rich Text Box.
CVE-2019-14730 1 Control-webpanel 1 Webpanel 2024-11-21 4.3 Medium
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a domain from a victim's account via an attacker account.
CVE-2019-14729 1 Control-webpanel 1 Webpanel 2024-11-21 4.3 Medium
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a sub-domain from a victim's account via an attacker account.
CVE-2019-14728 1 Control-webpanel 1 Webpanel 2024-11-21 4.3 Medium
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to add an e-mail forwarding destination to a victim's account via an attacker account.
CVE-2019-14727 1 Control-webpanel 1 Webpanel 2024-11-21 4.3 Medium
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to change the e-mail password of a victim account via an attacker account.
CVE-2019-14726 1 Control-webpanel 1 Webpanel 2024-11-21 5.4 Medium
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to access and delete DNS records of a victim's account via an attacker account.
CVE-2019-14725 1 Control-webpanel 1 Webpanel 2024-11-21 4.3 Medium
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to change the e-mail usage value of a victim account via an attacker account.
CVE-2019-14724 1 Control-webpanel 1 Webpanel 2024-11-21 7.5 High
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to edit an e-mail forwarding destination of a victim's account via an attacker account.
CVE-2019-14723 1 Control-webpanel 1 Webpanel 2024-11-21 4.3 Medium
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete a victim's e-mail account via an attacker account.
CVE-2019-14722 1 Control-webpanel 1 Webpanel 2024-11-21 4.3 Medium
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to delete an e-mail forwarding destination from a victim's account via an attacker account.